docs: add six interactive archify architecture diagrams - #41
Conversation
Adds docs/architecture/ — a set of self-contained, explorable HTML diagrams generated with archify, alongside their typed JSON sources so they can be regenerated and reviewed as text. - system.architecture — services, ownership and the links between them - position-hot-path.sequence — GPS frame to live map marker - tenant-isolation.workflow — credential to tenant-scoped RLS transaction - telemetry-lineage.dataflow — where a fix lands, what derives from it, and when it ages out - device-session.lifecycle — tracker connection states and refusals - deployment.architecture — production topology on Cloudflare, Vercel, Fly.io and the managed data services Content was verified against the code rather than the existing prose: recordPosition(), the ingest admission and sink path, withTenant/withSystem, the jobs scheduler task table, retention plan windows, and the fly.*.toml machine configs. The system and deployment diagrams pin repository evidence, so a cited path that disappears fails regeneration instead of going quietly stale. All six pass archify's showcase profile (9/9 artifact checks, 0 errors, 0 warnings) with browser-verified containment and text legibility at 1440x900, 1600x1000, 1920x1080 and 2048x1320. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016i4eitqukrs4RQwtvkTPU2
|
| Advisory | Package | Vulnerable | Patched | Path |
|---|---|---|---|---|
| GHSA-c83g-rgw3-j3cx — unbounded memory growth, eventual OOM | browserslist |
<=4.28.6 |
>=4.28.7 |
apps__web > autoprefixer > browserslist |
GHSA-73wf-gq98-2v4g — crash / prototype write via untrusted browserslist-stats.json |
browserslist |
<=4.28.6 |
>=4.28.7 |
apps__web > autoprefixer > browserslist |
Why it isn't this PR's: the diff touches only docs/ and README.md. It modifies no package.json and no pnpm-lock.yaml, so the lockfile this job audits is byte-identical to the one on main. pnpm audit reads the lockfile, so it produces the same result on both — this is a base-branch condition that surfaced here only because opening the PR ran the workflow today. main last ran security.yml successfully on 2026-08-31 (674840f), before these advisories were published; the workflow's scheduled runs on main have gone red the same way each time a new advisory lands.
I deliberately have not re-run the job. A re-run cannot help: the audit is deterministic against a fixed lockfile, so a second run would fail identically. Spending the re-run would prove nothing.
No fix PR exists to port, so rather than widening a docs PR with a dependency change, here is the proposed patch. It follows the convention already used in this repo for esbuild, hono, ip-address, nanoid, postcss, sharp and shell-quote:
"pnpm": {
"onlyBuiltDependencies": ["esbuild"],
"overrides": {
+ "browserslist": "4.28.8",
"esbuild": "0.28.1",
"hono": "4.12.34",…followed by pnpm install to regenerate pnpm-lock.yaml. Current resolution is browserslist@4.28.2, reached only through autoprefixer@10.5.0 in apps/web, so this is a patch-level bump within the same minor and should be low risk. 4.28.8 is the latest published version and satisfies the >=4.28.7 requirement in both advisories.
This belongs in its own PR so the dependency change is reviewable on its own terms, and because merging a security bump bundled into a documentation change is a poor audit trail. Happy to open that PR on request.
Every other check on this head is green: sast, secret-scan, sbom, mobile-dependency-audit, mobile-test (verify still running at the time of writing).
Generated by Claude Code
Brings in the browserslist advisory pin (#42) so dependency-audit runs against the fixed lockfile. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016i4eitqukrs4RQwtvkTPU2
Summary
Adds
docs/architecture/— six self-contained, explorable HTML diagrams of the platform, generated with archify, alongside their typed JSON sources so they can be regenerated and reviewed as text.system.htmlposition-hot-path.htmltenant-isolation.htmltelemetry-lineage.htmldevice-session.htmldeployment.htmlThe Mermaid diagrams in
docs/ARCHITECTURE.mdstay as the quick read; these are the detailed companions, and bothdocs/ARCHITECTURE.mdand the rootREADME.mdnow link to them. The data-lineage and device-session views have no counterpart in the existing docs.Content was verified against the code rather than the existing prose:
recordPosition(), the ingest admission and sink path,withTenant/withSystem, the jobs scheduler task table, retention plan windows, and thefly.*.tomlmachine configs. Thesystemanddeploymentdiagrams pinmeta.repositoryat674840fand cite 13 source paths between them, so a cited path that disappears fails regeneration instead of going quietly stale.Reviewer notes
src/and generating the HTML in CI — happy to switch.route: "drop"and explicit vertical endpoint sides were both rejected by the layout compiler as infeasible, so those edges use its automatic routes.Security and privacy
docs/ARCHITECTURE.md; no secrets, hostnames beyond what the repo already documents, or device identifiers.NOSUPERUSER NOBYPASSRLSapp role,app.tenant_idset transaction-locally, the reviewedSYSTEM_DATABASE_URLpaths) without altering it.Verification
Docs-only change: the diff touches nothing outside
docs/andREADME.md, so the application test suite is unaffected. Node dependencies were not installed in the environment this was authored in, so the commands below were not run — flagging that rather than ticking boxes:pnpm typecheck— not run (no application code changed)pnpm test— not run (no application code changed)pnpm build— not run (no application code changed)What was verified instead, per diagram:
archify deliver --quality showcase— 9/9 artifact checks, 0 errors, 0 warnings on all sixsystem(9 references) anddeployment(4 references)archify visual-checkin headless Chromium — containment and ≥6px projected text at 1440×900, 1600×1000, 1920×1080 and 2048×1320, light and dark🤖 Generated with Claude Code
https://claude.ai/code/session_016i4eitqukrs4RQwtvkTPU2
Generated by Claude Code